Vulnerability index

Browse CVEs

3,051 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Deserialization of Untrusted DataCWE-502 × clear
Enterprise Vault CRITICAL 9.8
CVE-2021-44677

An issue (1 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services th…

Fix: after 14.1.2
Fix from $2,300 2021-12-06
Enterprise Vault CRITICAL 9.8
CVE-2021-44678

An issue (2 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services th…

Fix: after 14.1.2
Fix from $2,300 2021-12-06
Enterprise Vault CRITICAL 9.8
CVE-2021-44679

An issue (3 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services th…

Fix: after 14.1.2
Fix from $2,300 2021-12-06
Thinkphp CRITICAL 9.8
CVE-2021-36564

ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\Adapte…

No fix yet
Fix from $2,300 2021-12-06
Thinkphp CRITICAL 9.8
CVE-2021-36567

ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\AbstractCache.

No fix yet
Fix from $2,300 2021-12-06
Ajaxpro.2 CRITICAL 9.8
CVE-2021-23758EPSS 89%

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET cla…

Fix: 21.10.30.1+
Fix from $2,300 2021-12-03
Ehrd HIGH 8.8
CVE-2021-43360

Sunnet eHRD e-mail delivery task schedule’s serialization function has inadequate input object validation and restriction, which allows a post-authen…

Mitigation only
Fix from $1,950 2021-12-01
Spring Advanced Message Queuing Protocol MEDIUM 6.5
CVE-2021-22095

In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new String object …

Fix: 2.2.19 / 2.3.11+
Fix from $1,600 2021-11-30
C1 Cms HIGH 8.8
CVE-2021-34992

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS 6.10. Authentication is required t…

Patch available
Fix from $1,950 2021-11-15
Shardingsphere Ui HIGH 7.5
CVE-2021-26558

Deserialization of Untrusted Data vulnerability of Apache ShardingSphere-UI allows an attacker to inject outer link resources. This issue affects Apa…

Fix: 5.0.0+
Fix from $1,950 2021-11-11
Daqfactory HIGH 7.8
CVE-2021-42698

Project files are stored memory objects in the form of binary serialized data that can later be read and deserialized again to instantiate the origin…

Fix: after 18.1
Fix from $1,950 2021-11-05
Experience Platform CRITICAL 9.8
CVE-2021-42237 KEVEPSS 98%

Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remot…

Mitigation only
Fix from $2,300 2021-11-05
Spring Advanced Message Queuing Protocol MEDIUM 6.5
CVE-2021-22097

In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a body for a me…

Fix: after 2.3.10
Fix from $1,600 2021-10-28
Call Recording CRITICAL 10.0
CVE-2019-19810

Zoom Call Recording 6.3.1 from Eleveo is vulnerable to Java Deserialization attacks targeting the inbuilt RMI service. A remote unauthenticated attac…

Mitigation only
Fix from $2,300 2021-10-28
Nameko HIGH 7.8
CVE-2021-41078

Nameko through 2.13.0 can be tricked into performing arbitrary code execution when deserializing the config file.

Fix: after 2.13.0
Fix from $1,950 2021-10-26
Storm CRITICAL 9.8
CVE-2021-40865EPSS 66%

An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (…

Fix: 1.2.4 / 2.1.1+
Fix from $2,300 2021-10-25
Connect CRITICAL 9.8
CVE-2021-40719

Adobe Connect version 11.2.3 (and earlier) is affected by a Deserialization of Untrusted Data vulnerability to achieve arbitrary method invocation wh…

Fix: after 11.2.3
Fix from $2,300 2021-10-21
Sassy Social Share HIGH 8.8
CVE-2021-39321

Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_sss_import_config AJAX action…

Patch available
Fix from $1,950 2021-10-21
Access Rights Manager HIGH 7.8
CVE-2021-35227

The HTTP interface was enabled for RabbitMQ Plugin in ARM 2020.2.6 and the ability to configure HTTPS was not available.

Fix: after 2020.2.6
Fix from $1,950 2021-10-21
Ops Cli CRITICAL 9.8
CVE-2021-40720EPSS 10%

Ops CLI version 2.0.4 (and earlier) is affected by a Deserialization of Untrusted Data vulnerability to achieve arbitrary code execution when the che…

Fix: 2.0.5+
Fix from $2,300 2021-10-15
Insider Threat Management Server HIGH 7.3
CVE-2021-40843

Proofpoint Insider Threat Management Server contains an unsafe deserialization vulnerability in the Web Console. An attacker with write access to the…

Fix: 7.11.2+
Fix from $1,950 2021-10-13
Sinec Nms HIGH 7.2
CVE-2021-33728

A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to upload JSON objects that are deser…

Fix: 1.0+
Fix from $1,950 2021-10-12
Java MEDIUM 6.7
CVE-2021-25738

Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution.

Fix: 11.0.1+
Fix from $1,600 2021-10-11
Zammad CRITICAL 9.8
CVE-2021-42090

An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled.

Fix: 4.1.1+
Fix from $2,300 2021-10-07
Panel HIGH 8.1
CVE-2021-41129

Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify the contents of a `confirmati…

Fix: 1.6.2+
Fix from $1,950 2021-10-06
Android HIGH 7.8
CVE-2021-0685

In ParsedIntentInfo of ParsedIntentInfo.java, there is a possible parcel serialization/deserialization mismatch due to unsafe deserialization. This c…

Patch available
Fix from $1,950 2021-10-06
Cwlviewer CRITICAL 9.8
CVE-2021-41110

cwlviewer is a web application to view and share Common Workflow Language workflows. Versions prior to 1.3.1 contain a Deserialization of Untrusted D…

Fix: 1.3.1+
Fix from $2,300 2021-10-01
Ddlutils CRITICAL 9.8
CVE-2021-41616

Apache DB DdlUtils 1.0 included a BinaryObjectsHelper that was intended for use when migrating database data with a SQL data type of BINARY, VARBINAR…

Mitigation only
Fix from $2,300 2021-09-30
Concrete Cms CRITICAL 9.1
CVE-2021-40102

An issue was discovered in Concrete CMS through 8.5.5. Arbitrary File deletion can occur via PHAR deserialization in is_dir (PHP Object Injection ass…

Fix: after 8.5.5
Fix from $2,300 2021-09-24
Gradle HIGH 8.1
CVE-2021-41588

In Gradle Enterprise before 2021.1.3, a crafted request can trigger deserialization of arbitrary unsafe Java objects. The attacker must have the encr…

Fix: 2021.1.3+
Fix from $1,950 2021-09-24